Sandworm-Linked UAC-0145 Exploits Fake Interviews to Deploy Malware
TL;DR. A Russian state-backed hacking group uses fake job interviews to deploy a custom VPN tool capable of executing commands on compromised systems. - UAC-0145, associated with Sandworm, targets organizations with sophisticated social engineering tactics. - The custom SuperOps RMM agent and remote access VPN bypass security and enable command execution. - Threat actors leverage these tools to maintain persistence and conduct further malicious activities within networks.
- Russian state-backed hacking group UAC-0145 uses fake job interviews as an initial access vector.
- The group deploys a custom VPN tool that functions as a remote access backdoor for command execution.
- Exploits include the SuperOps RMM agent, enabling broad system control and bypassing security measures.
- Victims are subjected to advanced social engineering, leading to significant security breaches.